This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revision Both sides next revision | ||
сервис_snortsam [2015/06/05 07:45] val [cisco router acl telnet] |
сервис_snortsam [2015/06/05 09:24] val [cisco router acl tftp] |
||
---|---|---|---|
Line 94: | Line 94: | ||
==== cisco router acl tftp ==== | ==== cisco router acl tftp ==== | ||
- | Настройка | + | === Настройка === |
<code> | <code> | ||
server# cat /tftpboot/snortsam.acl | server# cat /tftpboot/snortsam.acl | ||
Line 109: | Line 109: | ||
permit tcp any any established | permit tcp any any established | ||
deny ip any any log | deny ip any any log | ||
+ | end | ||
</code><code> | </code><code> | ||
server# cat snortsam.tftp | server# cat snortsam.tftp | ||
</code><code> | </code><code> | ||
- | copy tftp://192.168.X.1/ running-config | + | copy tftp://192.168.X.10/ running-config |
</code><code> | </code><code> | ||
server# cat snortsam.conf | server# cat snortsam.conf | ||
</code><code> | </code><code> | ||
... | ... | ||
+ | # ciscoacl 192.168.X.1 cisco cisco snortsam.acl|/usr/local/etc/snortsam/snortsam.tftp | ||
# ciscoacl 192.168.X.1 student/tacacs cisco snortsam.acl|/usr/local/etc/snortsam/snortsam.tftp | # ciscoacl 192.168.X.1 student/tacacs cisco snortsam.acl|/usr/local/etc/snortsam/snortsam.tftp | ||
- | # ciscoacl 192.168.X.1 student/tacacs cisco snortsam.acl|/etc/snortsam/snortsam.tftp | ||
- | </code><code> | ||
- | server# cd /tftpboot/ | ||
</code> | </code> | ||
- | Запуск | + | === Запуск === |
<code> | <code> | ||
+ | server# cd /tftpboot/ | ||
+ | |||
[server:/tftpboot] # snortsam /usr/local/etc/snortsam/snortsam.conf | [server:/tftpboot] # snortsam /usr/local/etc/snortsam/snortsam.conf | ||
</code> | </code> |